OSFI E-21 takes full effect September 1, 2026. Is your document vendor ready?
Every federally regulated Canadian financial institution must demonstrate operational resilience and third-party risk governance by the deadline — including where vendors store client data and how they document it. SideDrawer's Canadian data residency and continuous audit trails are a direct answer to what OSFI is now asking.
What is OSFI Guideline E-21?
OSFI Guideline E-21 is the operational resilience guideline issued by the Office of the Superintendent of Financial Institutions for federally regulated financial institutions in Canada — banks, insurance companies, trust companies, federal credit unions, and Canadian branches of foreign banks. It requires these institutions to demonstrate operational resilience and third-party risk governance, with full compliance required by September 1, 2026.
E-21 builds on OSFI Guideline B-10 (Third-Party Risk Management, in force since May 2024), which requires documented data handling provisions in every vendor contract, geographic data residency transparency, and continuous audit trails of third-party oversight. Some compliance guidance interpreting B-10 has also raised CLOUD Act exposure as a possible consideration for institutions using US-domiciled platforms — a point worth reviewing for any Canadian FRFI evaluating a US-hosted vendor.
Source: OSFI Guideline E-21 and OSFI Guideline B-10 (Office of the Superintendent of Financial Institutions)
Three requirements. Three direct answers.
OSFI B-10 names three specific examination points for third-party document and data vendors. Here is how SideDrawer answers each one.
Documented data handling provisions in every vendor contract
SideDrawer provides documented data handling terms as a standard part of every institutional agreement — ready for OSFI examination review, not assembled after the fact.
Geographic data residency transparency
SideDrawer offers Canadian data residency, with documented, verifiable answers to exactly where client data physically resides — the specific question OSFI examiners are now asking.
Continuous audit trails of third-party oversight
Every document interaction — upload, access, share, and sign — is logged automatically. Compliance evidence exists as a byproduct of normal operation, not a manual reconstruction.
Where does your vendor's data actually reside?
Some compliance guidance interpreting OSFI B-10 has raised CLOUD Act exposure as a possible consideration for institutions using US-domiciled platforms. It may be worth asking any vendor handling client documents where that data physically lives.
Questions Worth Asking
- Jurisdiction can depend on where the vendor is domiciled
- Data residency terms vary by vendor — worth confirming directly
- A consideration some compliance teams are reviewing under B-10
Canadian Data Residency
- Data resides in Canada, with documented residency terms
- Continuous audit trail on every document interaction
- Aligned with OSFI B-10 examination requirements
The vault is what makes AI adoption safe
Shadow AI doesn't announce itself — it shows up as an employee pasting a client statement into an AI tool to summarize it faster. A structured document vault doesn't stop AI use. It controls which data AI can reach.
Client documents in SideDrawer's vault cannot be accessed by unauthorized AI tools without passing through SideDrawer's governed access layer first.
Bank-grade encryption
deployed across North America
upload, access, sign, and share
Frequently Asked Questions
The window closes September 1, 2026.
Talk to our team before your next OSFI examination cycle begins.